LoadModule ssl_module modules/mod_ssl.so Listen 5000 Listen 35357 AuthType shibboleth ShibRequestSetting requireSession 1 require valid-user Alias "/secure" "/var/www/html/secure" ServerName https://merlin.hpc.rug.nl:5000 SSLEngine on SSLCertificateFile "/certs/merlin.hpc.rug.nl.crt" SSLCertificateKeyFile "/certs/merlin.hpc.rug.nl.key" SSLCACertificateFile "/certs/DigiCertCA.crt" UseCanonicalName On WSGIScriptAlias / /usr/bin/keystone-wsgi-public WSGIDaemonProcess keystone-public processes=5 threads=1 user=keystone group=keystone display-name=%{GROUP} WSGIProcessGroup keystone-public WSGIApplicationGroup %{GLOBAL} WSGIPassAuthorization On LimitRequestBody 114688 # Added for federation. WSGIScriptAliasMatch ^(/v3/OS-FEDERATION/identity_providers/.*?/protocols/.*?/auth)$ /usr/local/bin/keystone-wsgi-public/$1 = 2.4> ErrorLogFormat "%{cu}t %M" ErrorLog /var/log/apache2/keystone.log CustomLog /var/log/apache2/keystone_access.log combined = 2.4> Require all granted Order allow,deny Allow from all SetHandler shib ShibRequestSetting requireSession 1 AuthType shibboleth ShibExportAssertion Off Require valid-user ShibRequireSession On ShibRequireAll On AuthType shibboleth Require valid-user ShibRequestSetting requireSession 1 ShibRequireSession On ShibExportAssertion Off AuthType shibboleth Require valid-user ServerName https://merlin.hpc.rug.nl:35357 SSLEngine on SSLCertificateFile "/certs/merlin.hpc.rug.nl.crt" SSLCertificateKeyFile "/certs/merlin.hpc.rug.nl.key" SSLCACertificateFile "/certs/DigiCertCA.crt" UseCanonicalName On WSGIScriptAlias / /usr/bin/keystone-wsgi-admin WSGIDaemonProcess keystone-admin processes=5 threads=1 user=keystone group=keystone display-name=%{GROUP} WSGIProcessGroup keystone-admin WSGIApplicationGroup %{GLOBAL} WSGIPassAuthorization On LimitRequestBody 114688 = 2.4> ErrorLogFormat "%{cu}t %M" ErrorLog /var/log/apache2/keystone.log CustomLog /var/log/apache2/keystone_access.log combined = 2.4> Require all granted Order allow,deny Allow from all Alias /identity /usr/bin/keystone-wsgi-public SetHandler wsgi-script Options +ExecCGI WSGIProcessGroup keystone-public WSGIApplicationGroup %{GLOBAL} WSGIPassAuthorization On Alias /identity_admin /usr/bin/keystone-wsgi-admin SetHandler wsgi-script Options +ExecCGI WSGIProcessGroup keystone-admin WSGIApplicationGroup %{GLOBAL} WSGIPassAuthorization On